There are enough zero-day RCE exploits on both Android and iOS devices at this point that, if you're running phones that are that far out of date from security updates, you should basically just assume your device is fully compromised.
As stated above, many of the RCE exploits don't even involve any user interaction, so it's not like you can argue "well, I don't visit sketchy websites so I'm fine".
I mean, you're literally posting this complaint on a thread about a phone that is now legally bound to receive seven years of updates.
It feels very misplaced to complain about obsolescence on a thread in that context.
But yeah, this is a good news thread, thank you Google.